漏洞信息详情
PADL Software nss_ldap DNS查询应答拒绝服务攻击漏洞
- CNNVD编号:CNNVD-200208-141
- 危害等级: 高危
- CVE编号:
CVE-2002-0825
- 漏洞类型:
边界条件错误
- 发布时间:
2002-08-12
- 威胁类型:
远程
- 更新时间:
2006-09-21
- 厂 商:
padl_software - 漏洞来源:
MandrakeSoft -
漏洞简介
nss_ldap模块用于与LDAP服务器通信,可以查询和处理主机用户,用户组等信息的程序。
nss_ldap模块错误验证被截断的DNS查询应答,远程攻击者可以利用这个漏洞进行拒绝服务攻击。
nss_ldap没有正确检查由DNS查询返回而且被截断的应答数据,当处理截断的查询应答时可导致nss_ldap读取合法内存以外的地址,这将使nss_ldap崩溃,产生拒绝服务。看起来不能利用来执行任意指令,不过没有得到证实。
漏洞公告
厂商补丁:
MandrakeSoft
————
MandrakeSoft已经为此发布了一个安全公告(MDKSA-2002:075)以及相应补丁:
MDKSA-2002:075:nss_ldap update
链接:http://www.linux-mandrake.com/en/security/2002/2002-075.php” target=”_blank”>
http://www.linux-mandrake.com/en/security/2002/2002-075.php
补丁下载:
Updated Packages:
Linux-Mandrake 7.2:
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/7.2/RPMS/nss_ldap-202-1.2mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/7.2/SRPMS/nss_ldap-202-1.2mdk.src.rpm
Mandrake Linux 8.0:
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/8.0/RPMS/nss_ldap-202-1.2mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/8.0/SRPMS/nss_ldap-202-1.2mdk.src.rpm
Mandrake Linux 8.0/PPC:
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/8.0/RPMS/nss_ldap-202-1.2mdk.ppc.rpm
Mandrake Linux 8.1:
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/8.1/RPMS/nss_ldap-202-1.1mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/8.1/RPMS/pam_ldap-156-1.1mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/8.1/SRPMS/nss_ldap-202-1.1mdk.src.rpm
Mandrake Linux 8.1/IA64:
Mandrake Linux 8.2:
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/8.2/RPMS/nss_ldap-202-1.1mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/8.2/RPMS/pam_ldap-156-1.1mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/8.2/SRPMS/nss_ldap-202-1.1mdk.src.rpm
Mandrake Linux 8.2/PPC:
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/8.2/RPMS/nss_ldap-202-1.1mdk.ppc.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/ppc/8.2/RPMS/pam_ldap-156-1.1mdk.ppc.rpm
Mandrake Linux 9.0:
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/RPMS/nss_ldap-202-1.1mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/RPMS/pam_ldap-156-1.1mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.0/SRPMS/nss_ldap-202-1.1mdk.src.rpm
Single Network Firewall 7.2:
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/snf7.2/RPMS/nss_ldap-202-1.2mdk.i586.rpm
ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/snf7.2/SRPMS/nss_ldap-202-1.2mdk.src.rpm
上述升级软件还可以在下列地址中的任意一个镜像ftp服务器上下载:
http://www.mandrakesecure.net/en/ftp.php” target=”_blank”>
http://www.mandrakesecure.net/en/ftp.php
参考网址
来源: www.padl.com
链接:http://www.padl.com/Articles/PotentialBufferOverflowin.html